Omahub
← All plugins
R

X composer

by Ryan Macy

Compose X posts with a browser handoff by default or explicit paid API posting through the bundled backend.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
13c40e8
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
13c40e8
Reviewed
1 month ago

This is a well-engineered X (Twitter) composer plugin with a safe default browser-handoff mode and an explicitly opt-in paid API mode. The backend is stdlib-only, enforces strict file permissions, avoids logging secrets, and passes text via stdin/job files rather than shell interpolation. No malicious, obfuscated, or destructive behavior was found.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/rmacy/omarchytweet --enable
Widgets #bar #quickshell

bitr0t.omarchytweet

Compose X (Twitter) posts from the Omarchy bar.

Screenshots

Bar widget

X composer icon alongside Omarchy system widgets

Composer popover

Themed X composer popover with a sample post

Posting modes

Browser composer (default, free) — opens the X Web Intent URL via xdg-open. You press the final Post button in your browser. No API keys needed.

Paid API — posts directly to the X API (POST /2/tweets) with OAuth 1.0a signing. Explicitly opt-in; the backend refuses this mode unless paid_api = true and all four credential fields are non-empty.

Pricing is pay-per-use and changes over time. The X Developer Console (developer.x.com) is authoritative. As of writing, publishing costs roughly:

Content Approx. cost per post
Text-only $0.015
Contains a URL $0.20

Install

omarchy plugin add https://github.com/rmacy/omarchytweet.git --enable

Configure

mkdir -m 700 -p ~/.config/xtweet
cp ~/.config/omarchy/plugins/bitr0t.omarchytweet/config.example.toml ~/.config/xtweet/config.toml
chmod 600 ~/.config/xtweet/config.toml

Edit ~/.config/xtweet/config.toml to set paid_api and, if using the paid API, the four OAuth 1.0a fields. The backend also generates this template with correct permissions on first run.

Controls

  • Click the X icon in the bar to open the composer panel.
  • Enter submits; Shift+Enter inserts a newline; Escape dismisses.
  • The action button label reflects the active mode: Continue in X (browser) or Post (paid API).
  • The bar button tooltip also adapts: Compose on X vs New post.

Drafts persist across panel open/close cycles and are shared across monitors.

Optional CLI

The bin/xtweet wrapper resolves the backend relative to itself. Symlink it into your PATH:

ln -sf ~/.config/omarchy/plugins/bitr0t.omarchytweet/bin/xtweet ~/.local/bin/xtweet

Post text is always passed on stdin, never as a command-line argument:

printf '%s' 'Your post text here' | xtweet post

Other commands (mode, enqueue, status, active, ack, draft) pass through directly to the backend.

Exit codes: 0 posted or composer opened; 1 failed / busy / unknown; 2 usage error.

File architecture

backend.py              Posting backend (Python 3.11+ stdlib only)
Service.qml             Singleton service: backend IPC, draft state, job queue
Panel.qml               Per-monitor composer UI
manifest.json           Omarchy plugin metadata
config.example.toml     Configuration template
xtweet.png              Bar icon
preview.png             Marketplace preview (bar + composer)
screenshots/            Browser-free detailed UI captures
bin/xtweet              Optional CLI wrapper (resolves backend relative to itself)
tests/test_backend.py   Isolated stdlib backend regression suite
pyproject.toml          Poetry development metadata (runtime has no dependencies)
LICENSE                 MIT license

Runtime state (job files, locks) lives under $XDG_RUNTIME_DIR/bitr0t.omarchytweet. Credentials are read from ~/.config/xtweet/config.toml (0700 dir, 0600 file) and never copied into job files.

Development

omarchy plugin validate .
poetry run python tests/test_backend.py

Runtime never depends on Poetry.

Security

  • ~/.config/xtweet is created with mode 0700; config.toml with 0600. Symlinks, foreign owners, and group/other permission bits are refused.
  • OAuth secrets are never logged, echoed, or included in JSON output.
  • The Web Intent URL embeds draft text and is never returned in JSON or logs.
  • Post text arrives via stdin or job files — never via shell interpolation or command-line arguments.

Uninstall

omarchy plugin remove bitr0t.omarchytweet

Remove the optional CLI symlink and configuration if desired:

rm -f ~/.local/bin/xtweet
rm -rf ~/.config/xtweet

License

MIT — see LICENSE.